cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2627
Views
8
Helpful
1
Replies

Authorizing users based on ip subnet

rroulhac
Cisco Employee
Cisco Employee

Hello All,

Can we authorize a subset of users based on IP subnet in ISE 2.2?

I have found the CISCO AV PAIR of cisco-ip-pool= but not sure if this is looking at the endpoints IP and detecting that it is in the subnet range or not.

any assistance would be helpful.

--

Grace and Peace,

Robert E Roulhac Jr

Virtual Systems Engineer II

Cisco TSN (Technical Solutions Network)

rroulhac@cisco.com

Office: 919.5745455

1 Accepted Solution

Accepted Solutions

Charlie Moreton
Cisco Employee
Cisco Employee

Yes, you can.  First create the Condition by navigating to Policy > Policy Elements > Conditions > Network Conditions > Endstation Network Conditions.  Enter the information to include any IP Ranges and click Submit.

IP_Range.PNG

To use this in a Authorization Policy, navigate to you policy set and choose Select Existing Condition from Library.

IP_Range2.PNG

The choose Network Condition

IP_Range3.PNG

And finally select the Network Condition you created.

IP_Range4.PNG

Assign an Authorization Profile to the rule and Click Save.

View solution in original post

1 Reply 1

Charlie Moreton
Cisco Employee
Cisco Employee

Yes, you can.  First create the Condition by navigating to Policy > Policy Elements > Conditions > Network Conditions > Endstation Network Conditions.  Enter the information to include any IP Ranges and click Submit.

IP_Range.PNG

To use this in a Authorization Policy, navigate to you policy set and choose Select Existing Condition from Library.

IP_Range2.PNG

The choose Network Condition

IP_Range3.PNG

And finally select the Network Condition you created.

IP_Range4.PNG

Assign an Authorization Profile to the rule and Click Save.